Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,394
Total alertas
3047
Críticas
10075
Altas
8
Ransomware
1739
Esta semana
RSS
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-56090] Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerab…
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-56685] Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elemen…
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-56686] Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elemen…
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-59909] Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privil…
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Traversal vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-59910] Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elemen…
Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16471] Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Fun…
Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-19693] extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and nev…
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-15218] A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. Th…
A flaw was found in the maas-api and maas-controller ServiceAccounts within Red Hat OpenShift AI. These ServiceAccounts are granted cluster-wide permissions that exceed their operational requirements. An attacker who compromises the identity of these ServiceAccounts, either through a remote code execution vulnerability or by creating a malicious pod in the same namespace, could exploit these exces…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16137] In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credential…
In Progress ShareFile Storage Zones Controller v5.12.5 and below, a party with valid zone credentials can perform path traversal using resumable upload initiation endpoint, allowing the party to write arbitrary content to any location writable by the application's service account. This may result in the execution of attacker-supplied code.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16138] In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of…
In Progress ShareFile Storage Zones Controller v5.12.5 and below versions, unsafe deserialization of untrusted file metadata can allow a user with write access to a Network share to execute arbitrary code on the Storage Zones Controller host.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16139] In Progress ShareFile Storage Zones Controller versions <= 5.12.5 and <= 6.0.2, an authenticated zon…
In Progress ShareFile Storage Zones Controller versions
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-74997] In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk pl…
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via crafted placeholder replacement values. This issue only affects Roundcube instances using the markasjunk plugin with its cmd_learn driver.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-74998] In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style S…
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result in information disclosure or XSS (cross-site scripting) via MIME sniffing.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75002] In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desyn…
In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-14564] Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consul…
Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-16467] Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing F…
Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Fortilogger: before 6.1.5.9.
M Crítico vulnerabilidad
Hace 6 días
Vulnerabilidad crítica de desbordamiento de búfer en routers Wavlink WN531P3 y WN535M1
Se identificó una vulnerabilidad de desbordamiento de búfer en la pila (stack-based buffer overflow) en los routers Wavlink WN531P3 y WN535M1 versión V250922. La falla reside en la función strcpy del componente Export Pingortrace CGI (/etc/lighttpd/www/cgi-bin/export_pingortrace.cgi) y puede ser explotada remotamente manipulando el parámetro HTTP_COOKIE. El exploit ha sido divulgado públicamente, aumentando el riesgo para infraestructuras de telecomunicaciones y empresas en LATAM que utilizan estos equipos.
M Crítico vulnerabilidad
Hace 6 días
Vulnerabilidad crítica en openssl_encrypt < 1.4.0 compromete descifrado de datos
openssl_encrypt en versiones anteriores a 1.4.0 contiene una falla crítica en el módulo pqc.py que causa que fallos en desencapsulación KEM retrocedan silenciosamente a modo simulación, generando claves compartidas determinísticas a partir de solo 16 bytes de la clave privada. Un atacante que obtenga estos 16 bytes puede calcular la clave compartida y descifrar todos los textos cifrados, comprometiendo confidencialidad de datos sensibles en sistemas financieros, gubernamentales y empresariales de LATAM.
M Crítico vulnerabilidad
Hace 6 días
Vulnerabilidad crítica de omisión de autenticación en openssl_encrypt anteriores a v1.4.0
openssl_encrypt versiones previas a 1.4.0 contiene una vulnerabilidad de omisión de autenticación (CVSS 9.8) en pqc.py donde fallos en desencriptación AES-GCM activan una caída no autenticada a modo AES-CTR. Atacantes pueden modificar texto cifrado en tránsito para eludir verificación de integridad y ejecutar ataques de inversión de bits sin detección, comprometiendo confidencialidad e integridad de datos en sistemas financieros, gubernamentales y corporativos de LATAM.
M Crítico vulnerabilidad
Hace 6 días
Vulnerabilidad crítica en openssl_encrypt: credenciales PostgreSQL hardcodeadas exponen datos
Versiones de openssl_encrypt anteriores a 1.4.0 contienen credenciales de base de datos hardcodeadas en archivos de configuración del servidor, permitiendo acceso no autorizado a PostgreSQL desde la red local. Afecta principalmente a servidores en datacenters y nube en LATAM con estas versiones activas. El CVSS 9.8 indica riesgo crítico de exfiltración de datos sensibles.